yoinka

Lead Vulnerability Commander

Salesforce

RemoteVirginia - Washington DC Metro - RemoteSeniorH-1B sponsor company
Sign in to applyVerified 3h ago
Location
Virginia - Washington DC Metro - Remote
Work model
Remote
Level
Senior
H-1B history
498 approvals (FY2023)
Posted
23h ago

Skills

AWSGCPSalesforce

About this role

To get the best candidate experience, please consider applying for a maximum of 3 roles within 12 months to ensure you are not duplicating efforts. Job Category Enterprise Technology & Infrastructure Job Details About Salesforce Salesforce is the #1 AI CRM, where humans with agents drive customer success together. Here, ambition meets action. Tech meets trust. And innovation isn’t a buzzword — it’s a way of life. The world of work as we know it is changing and we're looking for Trailblazers who are passionate about bettering business and the world through AI, driving innovation, and keeping Salesforce's core values at the heart of it all. Ready to level-up your career at the company leading workforce transformation in the agentic era? You’re in the right place! Agentforce is the future of AI, and you are the future of Salesforce. The Experience As a Lead Vulnerability Commander on the Vulnerability Management team, you own the response to the most critical vulnerabilities end to end. As commanders on the most impactful cyber security team, we lead Salesforce’s security response for our Commercial and GovCloud environments while acting as the security executive liaison with Security and Business Leadership across the lifecycle of events. Frontier AI models have drastically decreased the time to exploit vulnerabilities and these need an incident-level response. You are that person and this is a driving role, not a passive coordination seat. You engage the owning engineering team, brief them on the fix and the remediation expectation, track the SLA, escalate to leadership when the clock is at risk, and run retros that feed process and tooling improvements back to Engineering partners. This candidate must be a U.S. citizen (U.S. born or naturalized) operating on U.S. Soil who does not hold dual citizenship with the ability to meet customer and government screening standards applicable to this role. What You'll Actually Be Doing Owning the critical vulnerability response end to end: engaging the owning engineering team, coordinating the fix, and driving the fix to closure. Briefing engineering owners on the required fix and the 24-hour expectation alongside Security stakeholders. Tracking each case against its SLA and escalating to leadership the moment a deadline is at risk, translating technical status into a clear read of risk, impact, and the decisions needed. Running a retrospective after each response to identify systemic causes and drive concrete prevention, not just closing the individual case. Taking those findings back to stakeholders to improve process and tooling. Partnering with the Threat Intelligence and Product Security teams to make the final call on if a vulnerability meets the criteria. Reporting volume, response times, and SLA adherence to Security and Engineering leadership. Running tabletop exercises and readiness drills so teams can meet the clock before a real critical finding lands. Building playbooks, tracking, and agentic automation that enables this process to not become the bottleneck.   You're Our Person If You Have: 8+ years in vulnerability management, incident response, security operations, or a closely related field. A track record of coordinating cross-team remediation under tight deadlines. Strong grasp of vulnerability severity, exploitability, and how critical findings are triaged and fixed. Experience working directly with engineering teams to drive fixes to completion. Ability to hold senior engineers and stakeholders to a shared deadline without formal authority over them. Comfort escalating to leadership with a clear, factual read of risk and status. Excellent written and verbal communication skills. Familiarity with SLA tracking, metrics, and retro-driven process improvement. Experience using or building AI-driven tooling for security triage, investigation, or decision support. Even Better If You Have: Technical knowledge of complex systems and Cloud environments (AWS, GCP,

Lead Vulnerability Commander at Salesforce, Virginia - Washington DC Metro - Remote | Yoinka